MB-490644b09dd5e68cfea06b6380672071ec83ae4a04dcbb1a61322dcabdf9e0d3
high
📛 Threat Title
Unknown: SOLICITUD DE COTIZACION.exe
Description
File type: exe. Size: 1011200 bytes. Tags: exe. Reporter: James_inthe_box. First seen: 2026-05-14 11:13:34.
Indicators of Compromise (5)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
cotizacion.exe
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/cotizacion.exe
IOC database
- Type
- domain
- Value
cotizacion.exe- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat MB-490644b09dd5e68cfea06b6380672071ec83ae4a04dcbb1a61322dcabdf9e0d3
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/cotizacion.exe
hash_imphash
f34d5f2d4577ed6d9ceec516c1f5a744
IOC database
- Type
- hash_imphash
- Value
f34d5f2d4577ed6d9ceec516c1f5a744- First seen
- Last seen
- Attached to this threat
- Appears in
- 650 threats
- Description
- imphash of URLhaus payload 61d424c2e3c5d8db…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
490644b09dd5e68cfea06b6380672071ec83ae4a04dcbb1a61322dcabdf9e0d3
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/490644b09dd5e68cfea06b6380672071ec83ae4a04dcbb1a61322dcabdf9e0d3
1 feed
IOC database
- Type
- hash_sha256
- Value
490644b09dd5e68cfea06b6380672071ec83ae4a04dcbb1a61322dcabdf9e0d3- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/490644b09dd5e68cfea06b6380672071ec83ae4a04dcbb1a61322dcabdf9e0d3
hash_sha1
6b7d1a14e7f0f6cd807e4602b79d31ca1d69789e
VT 50 / 75
1 feed
IOC database
- Type
- hash_sha1
- Value
6b7d1a14e7f0f6cd807e4602b79d31ca1d69789e- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 50 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win.Basic.C5882397 |
| Alibaba | malicious | TrojanPSW:MSIL/Agensla.fe959f6e |
| alibabacloud | malicious | Trojan[stealer]:MSIL/Kepavll.Gen |
| ALYac | malicious | Trojan.GenericKD.80143150 |
| Antiy-AVL | malicious | Trojan[PSW]/MSIL.Agensla |
| APEX | malicious | Malicious |
| Arcabit | malicious | Trojan.Generic.D4C6E32E |
| Avast | malicious | Win32:MalwareX-gen [Misc] |
| AVG | malicious | Win32:MalwareX-gen [Misc] |
| Avira | malicious | TR/W32.Agent |
| BitDefender | malicious | Trojan.GenericKD.80143150 |
| Bkav | malicious | W32.Malware.62BB9397 |
| CrowdStrike | malicious | win/malicious_confidence_100% (W) |
| CTX | malicious | exe.trojan.msil |
| Cylance | malicious | Unsafe |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | BackDoor.XWormNET.9 |
| Elastic | malicious | malicious (high confidence) |
| Emsisoft | malicious | Trojan.GenericKD.80143150 (B) |
| ESET-NOD32 | malicious | MSIL/Kryptik.AQEA trojan |
| F-Secure | malicious | Trojan.TR/W32.Agent |
| Fortinet | malicious | MSIL/Formbook.AA!tr |
| GData | malicious | Trojan.GenericKD.80143150 |
| malicious | Detected |
|
| huorong | malicious | Trojan/MSIL.Injector.nj |
| K7AntiVirus | malicious | Password-Stealer ( 005ce0261 ) |
| K7GW | malicious | Password-Stealer ( 005ce0261 ) |
| Kingsoft | malicious | MSIL.Trojan-PSW.Agensla.gen |
| Lionic | malicious | Trojan.Win32.Agensla.i!c |
| Malwarebytes | malicious | Malware.AI.4254202813 |
| McAfeeD | malicious | Trojan:Win/XWorm.NEN |
| Microsoft | malicious | Trojan:Win32/Kepavll!rfn |
| MicroWorld-eScan | malicious | Trojan.GenericKD.80143150 |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/Agent.JMU |
| Rising | malicious | Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:GlKEwH8t0dzlMSqaoFlInw) |
| Sangfor | malicious | Infostealer.Msil.AgentTesla.Vh17 |
| SentinelOne | malicious | Static AI - Suspicious PE |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | MSIL.Packed.12 |
| Tencent | malicious | Msil.Trojan.LummaStealer.Dnhl |
| Trapmine | malicious | malicious.moderate.ml.score |
| TrendMicro | malicious | Trojan.MSIL.MSILZILLA.TL0101EE26ZZ |
| TrendMicro-HouseCall | malicious | Trojan.Win32.VSX.PE04CA3 |
| Varist | malicious | W32/MSIL_Agent.KBL.gen!Eldorado |
| VBA32 | malicious | Malware-Cryptor.MSIL.Fuzzy.Heur |
| VIPRE | malicious | Trojan.GenericKD.80143150 |
| VirIT | malicious | Trojan.Win32.MSIL_Heur.A |
| ViRobot | malicious | Trojan.Win.Z.Kryptik.1011200.A |
| Yandex | malicious | Trojan.Igent.b6xFOk.1 |
Details From VirusTotal
Basic Properties
| MD5 | 2c3386eef926e484cd7ca46cad396a9b |
| SHA-1 | 6b7d1a14e7f0f6cd807e4602b79d31ca1d69789e |
| SHA-256 | 490644b09dd5e68cfea06b6380672071ec83ae4a04dcbb1a61322dcabdf9e0d3 |
| VHash | 216036651512f087383e6460 |
| SSDEEP | 12288:ShKreek9DMYBUwo92piHlMmau1ouSl1rFumN2H8+9VL72BwzupW9:SX2PCmQui1rBgc+9jR |
| TLSH | T1E625BF2D368F884DD591EB788F3337D41770D47258F2D3567F8C5338AA2AAE59A8C242 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| File size | 987.5 KB |
History
| Creation date | 2025-02-26 01:47 UTC |
| First seen on VirusTotal | 2026-05-13 14:02 UTC |
| Last submission | 2026-05-14 11:15 UTC |
| Last analysis | 2026-06-13 06:01 UTC |
| Last modified on VirusTotal | 2026-06-20 02:56 UTC |
Known Names
223532X.exepowerpoint.exeSOLICITUD DE COTIZACIÓN.exeCOTIZACIÓN TEK_Quality.exe_490644b09dd5e68cfea06b6380672071ec83ae4a04dcbb1a61322dcabdf9e0d3.exeCOTIZACI N TEK_Quality.exeg7fk0tvha.exe
hash_md5
2c3386eef926e484cd7ca46cad396a9b
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/2c3386eef926e484cd7ca46cad396a9b
2 feeds
IOC database
- Type
- hash_md5
- Value
2c3386eef926e484cd7ca46cad396a9b- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/2c3386eef926e484cd7ca46cad396a9b
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 1011200 bytes. Tags: exe. Reporter: James_inthe_box. First seen: 2026-05-14 11:13:34.
Remediations (8)
-
web:any.run
Online sandbox report for Solicitud de cotizacion.exe , tagged as agenttesla, verdict: Malicious activity
-
web:any.run
Online sandbox report for Solicitud de cotizacion.exe , tagged as netreactor, auto-startup, xworm, remote, verdict: Malicious activity
-
web:learn.microsoft.com
I understand you're seeing " Remediation Incomplete" after stopping the threat removal. Just to confirm, are you using Microsoft Defender? Since the scan was interrupted, the best step now is to run a Microsoft Defender Offline scan. This will restart your PC and scan before Windows loads, helping remove stubborn threats. To do this, go to:
-
web:support.microsoft.com
CAUTION After the mitigation for this issue is enabled on a device, meaning the mitigations have been applied, it cannot be reverted if you continue to use Secure Boot on that device. Even reformatting of the disk will not remove the revocations if they have already been applied. Please be aware of all the possible implications and test thoroughly before you apply the revocations that are ...
-
web:www.joesandbox.com
Sample Name: Solicitud_de_cotizacion.exe Cookbook: default.jbs Time: 08:26:33 Date: 10/08/2023 Version: 38.0.0 Beryl
-
web:www.joesandbox.com
Automated Malware Analysis - Joe Sandbox Management Report General Information Sample name: Solicitud de cotizacion.exe Analysis ID: 1420329 MD5 ...
-
web:www.joesandbox.com
The malware allocates memory in these foreign processes and injects a PE file, effectively using MSBuild.exe as a host for its malicious payload. One of the injected MSBuild.exe processes subsequently spawns WmiPrvSE.exe, indicating further process manipulation or injection.
-
web:www.joesandbox.com
Play interactive tourEdit tour Windows Analysis Report Solicitud de cotizacion.exe
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.